Upstream information
Description
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.Upstream Security Advisories:
SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
| CVSS detail | CNA (SUSE) |
|---|---|
| Base Score | 8.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | Required |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | None |
| CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- GHSA-6vpq-mf48-9794, published Thu Sep 24 01:02:29 CEST 2026
SUSE Timeline for this CVE
CVE page created: Thu Sep 24 12:06:49 2026CVE page last modified: Mon Sep 28 21:46:08 2026